CVE-2024-38619
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2024-38619 is a vulnerability in the Linux kernel's USB storage driver, specifically in the alauda component, discovered and disclosed on June 20, 2024. The vulnerability affects the media initialization process in the USB storage alauda driver, where the member 'uzonesize' of struct alaudainfo remains 0 if alaudainit_media() fails (NVD).

Technical details

The vulnerability occurs in the USB storage alauda driver where a potential divide-by-zero error can occur in alaudareaddata() and alaudawritelba() functions when the media initialization fails. The fix involves adding a 'mediainitialized' member to struct alaudainfo, modifying the condition in alaudacheckmedia() to ensure proper first initialization, and adding error checking for the return value of alaudainitmedia() (Kernel Commit).

Impact

If exploited, this vulnerability could lead to a denial of service condition through a system crash when attempting to perform read or write operations on affected USB storage devices. The vulnerability has been assigned a CVSS v3.1 score of 5.5 (Low severity) with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (Red Hat).

Mitigation and workarounds

The vulnerability has been patched in various Linux kernel versions. Updates are available for multiple distributions including Ubuntu 24.04 LTS (noble), 22.04 LTS (jammy), 20.04 LTS (focal), and 18.04 LTS (bionic). Red Hat has also released fixes for RHEL 8 and RHEL 9 systems (Ubuntu Security, Red Hat Security).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40343MEDIUM6.4
  • Linux KernelLinux Kernel
  • kernel-rt-modules-internal
NoYesDec 09, 2025
CVE-2025-40342MEDIUM6.4
  • Linux KernelLinux Kernel
  • kernel-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40341MEDIUM5.1
  • Linux KernelLinux Kernel
  • linux-nvidia-tegra
NoYesDec 09, 2025
CVE-2025-40345N/AN/A
  • Linux KernelLinux Kernel
  • kernel-headers
NoYesDec 12, 2025
CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management